CLAIMS 

What is claimed is: 

V A system for tracking network session information, the system 
comprising.: 

an information source module having a source information input and a 
standarciized information output, a source information corresponds to 
network ifcsage information, a standardized information corresponds to the 
network usage infomiation transformed into a standard format; 
a first program having at least a first standardized information input and an 
enhanced data outpV a first standardized information input corresponding 
to the standardized information, an enhanced data corresponding to the 
standardized data after at\east a partial transformation, the at least partial 
transformation being defineM according to a data record format; 
a second program having at least kfirst enhanced data input and a data record 
output, the first enhanced data cotaresponding to the enhanced data, a data 
record corresponding to the first d^an^d cteta, the data record being 
formatted according to the data recordVormat; 
a database storing the data record; and \ 

wherein the second program merges duplicate <&ta records that represent the 
same network usage information. \ 

2. The system of claim 1 wherein the at least partial\transformation is 
defined from a data enhancement procedure, and wherein the data Record format 
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ifacludes a. -plurality of fields and wherein the data enhancement procedure defines how 
the standardized information is to be transformed into the plurality of fields of the data 
record format. 

3. \ The system of claim 2 wherein the data enhancement procedure 
includes at least a field enhancement wherein the field enhancement defines a source 
for a predetermined field in the plurality of fields. 

4. TheNsystem of claim 2 wherein the data enhancement procedure 
includes at least a fielU enhancement wherein the field enhancement defines a function 
to be applied to at least apportion of the standardized data. 

5. The system of claim 2 wherein the data enhancement procedure defines 
a plurality of field enhancements, wherein each field enhancement defines network 
usage information to be stored in\the plurality of fields. 

6. The system of clahn2 further comprising a second information source 
module, the second information sourceVnoduIe having a second source information 
input and a second standardized information output, a second source information 
corresponds to a second network information, a seopnd standardized information 


ran; 


into a standard format, 
es a first definition of at least a 


corresponds to the second network information 
and wherein the data enhancement procedure i 

first field in the plurality of fields being from the standardized information, and at 
least a second definition of a second field in the pluralit^of fields being from the 
second standardized information. 

7. The system of 6 further comprising a proxy server and a domain name 
system (DNS) server, and wherein the information source modulesreceives the 
network usage information from the proxy server, and wherein the second information 
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)urce module receives the second network information from the DNS server, and 
whVein the first definition defines that a source IP address supplied by the proxy . 
server\hould be put into the first field, and wherein the second definition defines a 
URL supplied by the DNS server should be put into the second field. 

8. \ The system of claim 1 wherein the second program manages the first 
program and the information source module. 

9. The system of claim 1 wherein the second program causes the data 
record to be stored in the database. 

10. The system of claim 1 wherein the information source module is 
configured to receive theynetwork usage information from a predetermined network 
device. 

11. The system oficlaim 1 wherein the at least partial transformation 
includes policy-based data aggregation which defines how network usage data should 
be aggregated. 

12. The system of claim[^herein/fie network usage information includes 
IP session data. 

13. The system of claim 1 wherein the data format includes a plurality of 
fields including a source IP field, a destination IP field, a source host field, a 
destination host field, a seivice type field, a date and time field, a duration field, a 
total number of bytes field, and a counter field. \ 

14. The system of claim 1 further comprising a customer care and billing 
system coupled to the database, the customer care and Billing system for accessing the 
database to generate a bill from the data record. 

15. A network usage accounting system comprising: 
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\^n information source module coupled to receive network information from a 
network device; 

a gatherer coupled to receive the network information source module, the 
gatherer for performing data enhancements on the network information to 
create a plurality of data records; 
a central database storing the plurality of data records; and 
a central event manager coupled to receive the plurality of data records, the 
central event manager merging duplicate records in the plurality of data 
records, the duplicate records representing the same network usage 
information. 

16. The system of claim 15 wherein the information source module is 
configured to receive network information from a network device chosen from the 
group of network devices consisting of a proxy server, a domain name service server, 
a firewall, a RADIUS server, and a rautei/ 



1 7. The system of clairrj 1 Sjfyhefein the gatherer performs filtering and 
aggregation on the network information. 

18. The system of claim 15 whe\ein the plurality of data records have a 
predefined data format comprising a pluralitAof fields, and wherein the data 
enhancements includes at least a first data field^nhancement to enhance the network 


\ 


\ 


information to fill in the first data field. 

19. The system of claim 18 wherein the fitst data field corresponds to a 
source IP address field and wherein the data enhancement includes extracting a source 


EP address value from the network information. 


\ 
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\ 20.- - The system of claim 18 wherein the first data field corresponds to a 

lame field and wherein the data enhancement includes requesting a URL name 
from a domain name service server. 

2 1 . \ A method of gathering and aggregating network usage information 
from a set of network devices, the system using at least a first program and a second 
program coupled \n communications, the method comprising: 

accessing network communications usage information; 

filtering and aggregating the network communications usage information 
using the first brogram; 

completing a pluraliW of data records from the filtered and aggregated network 
communications uSage information, the plurality of data records 
corresponding to netWrk usage by a plurality of users; 

storing the plurality of datarecords; and 

merging duplicate records in\he plurality of data records. 

22. The method of claim 2 IwlWein completing the plurality of records 
includes accessing user account information. 

23. The method of claim 2 1 wherein completing the plurality of records 
includes for each data record determining a corresponding source IP address, a 
corresponding URL, a corresponding type of servke used, and a corresponding 
amount of time used. \ 

24. The method of claim 21 wherein the system includes a third program 
coupled in communications with at least the second program and wherein completing 
the plurality of records includes accessing the third program tis> determine network 
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accounmnformation and including the network account information in at least a first 
record in the plurality of records. 

25. \The method of claim 2 1 wherein merging the duplicate records 
includes comparing a plurality of fields in the data records to identify data records 
corresponding to the same network session and merging the corresponding records. 

26. The method of claim 2 1 wherein merging the duplicate records 
includes automatically aeleting a duplicate record. 

27. The method of claim 21 farther comprising using the second program 
to automatically update the filtering and aggregation performed by the first program. 

28. A network usagfe tracking system comprising: 

means for accessing netwbrk communications usage information; 
means for filtering and aggregating the network communications usage 

information using the firstWogram; 
means for completing a plurality^ f data records from the filtered and 

aggregated network communications us^e infonpdfion, the plurality of 
data records corresponding to nerofoiVusage by a plurality of users; 
means for storing the plurality of data records; and 
means for merging duplicate records in the plurality of data records. 

29. The network usage tracking system of claim 29 wherein the means for 
completing the plurality of data records includes one or more networked computers 
running one or more programs. 

30. The network usage tracking system of claim 29 \^herein the means for 
storing the plurality of data records includes a relational database. 
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3 k- - The netWtojcylisase tracking system of claim 29 wherein the means for 
storing the plurality of data rectus includes an object database. 


0/ 
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